SignalGate Is Driving the Most US Downloads of Signal Ever
wired.com
wired.com
> the week’s rate of adoption has been twice that of a typical week for 2025, which in turn was twice that of a typical week the same time last year.
Market penetration here is getting significant enough for more and more people.
[1] https://signalapp.nl/signal-app-nieuws/nederland-top-5-land-...
[2] https://signalapp.nl/signal-app-nieuws/nederlanders-kiezen-m...
Signal is, alas, merely a project. It will never morph into something like email that can withstand server running entities disappearing. So huge popularity could actually be a bad thing...
Signal is an incredibly lightweight design. If all users donated $0.60/year, or 5¢/month, that would sustain operations and overhead.
Compared to most other services, that's an insanely low cost per user.
EDIT: It's actually way less than even what I remembered - they only need about $0.60/user/year in order to break even, not $3/user/month.
Apparently so, since Signal broke even last year.
That's way, way lower than most other services, including most messaging services.
And donations aren't Signal's only source of revenue. Over a third comes from other sources.
> So Signal probably needs something like $30-40/month from people who actually donate, which seems unlikely.
Well, they broke even last year, so apparently it does work out.
Price points are location-dependent, which is why it's a nice round figure for you in GBP even though Signal is not based in the UK.
Also, as you noted, they accept donations outside the app.
(and what's more, I disagree with your premise. I think I'd everyone donated, the cost would be very spread out and it would be shockingly affordable, especially relative to the benefits we get)
Running chat apps doesn't have to be super expensive if you know what you're doing.
Plus, you never know when a MAGA will share incriminating info with you. Extra bonus!
No need to speculate; The Atlantic has the deets.
https://www.theatlantic.com/politics/archive/2025/03/signal-...
From the first screenshot: "Disappearing message time was set to 1 week."
They illegally fired the watchdogs put in place after Nixon (practically the only fucking useful thing we did about that—the laughably weak handling of the Watergate affair, and, shortly after, Iran-Contra, sent us well down the path we're possibly seeing the end of now) as one of their first acts, and nothing bad happened. Nothing they've done to evade legally-required scrutiny and oversight has brought them any trouble at all so far. Why would they stop?
Get your phone rooted by pegasus or whatever the newest chinese/israeli/whoever 0 click exploit and your fancy signal data is wide the fuck open. It's literally insane to me.
Well, also the entire government said as much, including the the AG, whose belief is a sitting President can't be indicted, and SCOTUS, who claims basically, that the President can't engage in illegal acts.
The only theoretical mechanism left is impeachment, but if the impossible happens and Congress does vote to remove, the administration will ignore it, or have SCOTUS rule against it. It just depends on how above board they care to pretend to make it look.
The other portion either finds him annoying or despises him with an ire that few outside the US can comprehend.
... which very much does not include most of the contents of the exchanges in question.
A similar gross error / crime was committed at the beginning of the war in Somalia, and was in the view of some the single action that contributed the most to US ground forces being pulled into the conflict. In that case, a missile was fired into a meeting room where tribal leaders were conferring.
Violators are immediately arrested and charged. I hate to see top-level exceptions to both record-keeping and mishandling of classified information. That's where they do the most damage.
As others have noted, the flaw in using Signal on consumer phones is due to vulnerabilities in the phone itself. And it was wrong to use consumer phones.
That said, I was recommending Signal to friends in order to have online discussions, using the conferencing feature, since it is cross-platform and cross-device. However, one friend lost their Apple login and can't install software on their phone. I sent a very long explainer on how to reset it.
Guess I'll try face-time conferencing, which works on Apple Devices [0] and will work with others via web [1]. Requires ios 15 or Monterey to initiate.
We have been using free, limited, zoom sessions.
[0] https://support.apple.com/en-us/111767 [1] https://support.apple.com/en-us/109364
How secure are those?
Signal makes it very difficult to even tell what parties are talking to each other (though if you have nation-state-level internet tracking, you can probably tell.)
Signal doesn't know anything about you except your number or screenname, when you signed up, and when you were last active.
Zoom is none of those things and the grandparent commenter has no idea what they're talking about.
>and the grandparent commenter has no idea what they're talking about.
What is this all about? I can't really see what you seem to disagree with?Using a public smartphone to conduct discussions about classified information is straight crazy. E2E encrypted or not.
If I'm getting that wrong, ignore me, if I'm not, could you expand that? I don't follow how signal did anything wrong here, or was in any way responsible.
The mobile app is polished and exists for both Android and iOS.
Throw it up on a budget VPS host and you have E2E video calling without any MiTM.
Signal still is hosted in the US, do we know how much they will fight if the government asks it to retrieve someone's messages? I don't know if I trust messaging apps that are already pandering to the administration to keep my data safe or fight to not decrypt my data.
They could at any point push an update that decrypts your messages locally and pushes them decrypted to a server. The only way to prevent this would be to verify each binary update to signal matches the source code, and no modifications have been made to the source to do this.
Is that part of your "signal update" routine?
I don't know the latest details about Android/iOS app signing, but presumably reproducible builds + sufficiently strong signing would make it secure enough for most users. For those who are truly paranoid, then can build it themselves (subject to their own device OS's requirements, which are hardly a unique problem to Signal).
In short, Signal's security should be as good as any mobile app can be, and can be even better if you're willing to put in legwork.
They haven't, but if they decide they want to what's technologically stopping signal from:
1. Making an update that doesn't exist in git which pushes decrypted messages to their server when you launch the app
2. Push this update to the app store
If a government ever compelled them to?
When was the last time you checked what updates have been made to the git repo?
Of course what you're saying is "technically" possible to avoid signal changing code and circumventing encryption, but show me one person who does a check of all the changes to signal source(and verified the binary matches) before they let their app store update it and they launch it...
Everyone I know has signal auto-update through the app store and don't even know it updated until after they launch it.
I understand the point about the app being distributed by the same people who run the service, but it's much harder to hide shenanigans with a local app versus a web app, especially when the app is open source.
All I'm getting at is that any company that distributes code to you and tells you they can't see your data is lying. They just don't want to access your data right now.
I would suggest people understand this and position themselves accordingly security-wise.
If that means not using signal because its not secure enough then ok.
If that means continuing to use signal with the understanding that it's only secure until signal decides they want your data(or a gov forces them to), then ok
Splitting management of an app and service is the exact solution. If signal can't control when to push updates to your phone then they can't control when they want to break encryption.
In your compromised browser example we understand that browsers have an interest in imementing HTTPS correctly and treat them accordingly. That's part of the reason the market is dominated by 2 engines that do their development as much in the public as possible
Most actions that are on the record, with classified data properly conveyed through their "high side" inboxes and properly archived, will have those records accessible to special counsel or historical analysts. If, as I suspect, most of the current cabinet's principals committees are meeting over Signal, the records of those communications will be conspicuously absent.
It's not like these guys are masterminds meticulously generating compelling and consistent alternate records in the SCIF, then also pulling out their phones and telling most of the same people most of the same things in group chat messages. They're just not having the discussions in the SCIF at all, and that will be evident to anyone who cares to investigate.
They aren't pandering to the government either. In fact they jokingly made fun of the US administration for this signal mistake.
Signal hasn't been pandering to the US government. All their previous behavior is that they would tell off the government if asked to add a backdoor. Keep in mind that Signal is non-profit, not company trying to make money.
All cryptosystems are vulnerable to compromised devices and $5 wrenches.
Signal also does not think that warrant canaries pass legal muster.
But it's still probably the best option. And if you're concerned by those risks I think building and auditing the public source code instead of relying on app store distribution would mitigate.